Browse all 10 CVE security advisories affecting GL-Inet. AI-powered Chinese analysis, POCs, and references for each vulnerability.
GL-Inet develops compact routers and network devices for small businesses and home users, focusing on easy deployment and wireless connectivity. Historically, their products have faced multiple remote code execution vulnerabilities, cross-site scripting issues, and privilege escalation flaws, often stemming from inadequate input validation and default configurations. With five CVEs documented, security researchers have identified weaknesses in web interfaces and firmware that could allow unauthorized access. While no major public incidents have been widely reported, the consistent pattern of vulnerabilities suggests potential risks for unpatched deployments, emphasizing the need for regular updates and proper hardening of these networking solutions.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-18616 | GL-iNet GL-MT3000 wg-server.so Native Plugin glc server.set_peer command injection — GL-MT3000 CWE-77 | 9.8 | Critical | 2026-08-03 |
| CVE-2026-18615 | GL-iNet GL-MT3000 wg-server.so Native Plugin glc wg-server.generate_publickey command injection — GL-MT3000 CWE-77 | 9.8 | Critical | 2026-08-03 |
| CVE-2026-18614 | GL-iNet GL-MT3000 s2s.so Native Plugin glc s2s.enable_echo_server command injection — GL-MT3000 CWE-77 | 9.8 | Critical | 2026-08-03 |
| CVE-2026-18613 | GL-iNet GL-MT3000 plugins.so Native Plugin glc plugins.set_config injection — GL-MT3000 CWE-74 | 9.8 | Critical | 2026-08-03 |
| CVE-2026-18612 | GL-iNet GL-MT3000 plugins.so Native Plugin glc plugins.install_package command injection — GL-MT3000 CWE-77 | 9.8 | Critical | 2026-08-03 |
This page lists every published CVE security advisory associated with GL-Inet. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.